# Repository Manager 2

Nexus Repository 2 was sunsetted on June 30, 2025.

See [Upgrade from Nexus Repository 2](https://help.sonatype.com/en/upgrade-from-nexus-repository-2.html "Upgrade from Nexus Repository 2")

The Nexus Repository 2 documentation is no longer available on our help site. Download a [PDF copy](https://download.sonatype.com/nexus/2/Sonatype%20Nexus%20Repository%202%20Help.pdf) of the documentation.

## [Download Sonatype Nexus Repository 2](https://help.sonatype.com/en/repository-manager-2.html#download-sonatype-nexus-repository-2_body)

**Nexus Repository Manager 2 Pro** is a distribution with features that are relevant to large enterprises and organizations that require complex procurement and staging workflows in addition to more advanced LDAP integration, Atlassian Crowd support, and other development infrastructure.

Nov 13, 2024

This release includes dependency changes that may require configuration changes before the upgrade. Please read [the release notes](https://help.sonatype.com/en/repository-manager-2.html#2024-nexus-repository-2-release-notes "2024 Nexus Repository 2 Release Notes") before upgrading.

- **[nexus-professional-2.15.2-03-bundle.tar.gz](https://download.sonatype.com/nexus/professional-bundle/nexus-professional-2.15.2-03-bundle.tar.gz)** \- [MD5](https://download.sonatype.com/nexus/professional-bundle/nexus-professional-2.15.2-03-bundle.tar.gz.md5), [SHA1](https://download.sonatype.com/nexus/professional-bundle/nexus-professional-2.15.2-03-bundle.tar.gz.sha1), [ASC](https://download.sonatype.com/nexus/professional-bundle/nexus-professional-2.15.2-03-bundle.tar.gz.asc)

- **[nexus-professional-2.15.2-03-bundle.zip](https://download.sonatype.com/nexus/professional-bundle/nexus-professional-2.15.2-03-bundle.zip)** \- [MD5](https://download.sonatype.com/nexus/professional-bundle/nexus-professional-2.15.2-03-bundle.zip.md5), [SHA1](https://download.sonatype.com/nexus/professional-bundle/nexus-professional-2.15.2-03-bundle.zip.sha1), [ASC](https://download.sonatype.com/nexus/professional-bundle/nexus-professional-2.15.2-03-bundle.zip.asc)

**Nexus Repository Manager 2 OSS** is a repository manager that can be freely used and is distributed under the Eclipse Public License (EPL Version 1).

- **[nexus-2.15.2-03-bundle.tar.gz](https://download.sonatype.com/nexus/oss/nexus-2.15.2-03-bundle.tar.gz)** \- [MD5](https://download.sonatype.com/nexus/oss/nexus-2.15.2-03-bundle.tar.gz.md5), [SHA1](https://download.sonatype.com/nexus/oss/nexus-2.15.2-03-bundle.tar.gz.sha1), [ASC](https://download.sonatype.com/nexus/oss/nexus-2.15.2-03-bundle.tar.gz.asc)

- **[nexus-2.15.2-03-bundle.zip](https://download.sonatype.com/nexus/oss/nexus-2.15.2-03-bundle.zip)** \- [MD5](https://download.sonatype.com/nexus/oss/nexus-2.15.2-03-bundle.zip.md5), [SHA1](https://download.sonatype.com/nexus/oss/nexus-2.15.2-03-bundle.zip.sha1), [ASC](https://download.sonatype.com/nexus/oss/nexus-2.15.2-03-bundle.zip.asc)

The Sonatype GPG key for verifying the install binaries can be obtained from [0374CF2E8DD1BDFD](https://keys.openpgp.org/search?q=0374CF2E8DD1BDFD)

_Nexus Repository OSS is distributed with Sencha Ext JS pursuant to a FLOSS Exception agreed upon between Sonatype, Inc. and Sencha Inc. Sencha Ext JS is licensed under GPL v3 and cannot be redistributed as part of a closed source work._

## [2024 Nexus Repository 2 Release Notes](https://help.sonatype.com/en/repository-manager-2.html#2024-nexus-repository-2-release-notes_body)

### Repository Manager 2.15.2

**Nov 13, 2024**

#### Important Vulnerability Fixes

This release fixes a Remote Code Execution vulnerability through which an attacker with privileges to publish content could upload a specially crafted file that would result in Nexus Repository attempting to execute embedded commands upon retrieval. See [CVE-2024-5082](https://support.sonatype.com/hc/en-us/articles/30694125380755) for details.

This release also fixes a Stored XSS vulnerability through which an attacker with privileges to publish content could upload a specially crafted file that includes embedded JavaScript. If that file is viewed by an authenticated user, the JavaScript could execute product features available to the authenticated user. See [CVE-2024-5083](https://support.sonatype.com/hc/en-us/articles/30693989411987) for details.
